The challenge
Patient data flowing through a cluster with public endpoints, long-lived credentials, and no audit trail — weeks before a funding round that required proof of compliance.
How I approached it
- Private EKS endpoints with sealed secrets and external secret rotation
- Network policies and admission control on every namespace
- Immutable audit trails shipped to a locked log account
- Evidence packs mapped control-by-control for the auditors
The outcome
Compliant in six weeks, audit passed first time, and the attack surface measured 40% smaller than the starting estate.
Stack: Amazon EKS · Sealed Secrets · Kyverno · AWS Audit Manager